PT-2025-52367 · Vega+1 · Vega+1

Ismisepaul

+1

·

Published

2025-12-18

·

Updated

2026-02-24

·

CVE-2025-68385

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Vega (affected versions not specified)
Description An issue exists where improper input neutralization during web page generation allows an authenticated user to embed a malicious script in content served to web browsers. This results in cross-site scripting (XSS) via a method in Vega, bypassing a previous XSS mitigation. The issue allows for browser-side script execution and potential data theft through Vega charts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2025-68385
BIT-KIBANA-2025-68385
CVE-2025-68385

Affected Products

Red Os
Vega